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IN THE CLAIMS 
Amended claims follow: 

1 * (Currently Amended) A computer program produc t_embodied on a computer 
readable medium operable for controlling a computer to identify a computer file as 
potentially containing malware, said computer program product comprising: 

searching code operable to search within said computer file for text data 
containing one or more target words that match at least one of a word or a characteristic 
of a word within a predetermined word library; 

context identifying code operable to identify a context within said computer file 
of said one or more target words; and 

file identifying code operable if said context matches one or a predetermined set 
of contexts to identify said computer file as potentially containing malware: 
wherein said predetermined word library includes one or more of: 

words that are names associated with known malware authors: 
word format characteristics that are indicative of words being part of a 
message embedded within said computer file by a malware author: and 

word suffix characteristics that are indicative of words being part of a 
message embedded within said computer file by a malware author: 
wherein said predetermined set of contexts includes one or more of: 
within a script portion of a webpa ge; 
within a comment of a weboage: and 
within a predetermined proximity to another target word . 

2. (Cancelled) 

3, (Cancelled) 
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4. (Original) A computer program product as claimed in claim 1 , wherein, if said 
computer file is identified as potentially containing malware, then malware found code 
triggers one or more malware found actions. 

5. (Original) A computer program product as claimed in claim 4, wherein said 
malware found actions include one or more of: 

quarantining said computer file; 
deleting said computer file; 

issuing a warning message concerning said computer file; and 
deleting a portion of said computer file suspect of containing malware. 

6. (Original) A computer program product as claimed in claim 1 , wherein, if said 
computer file is identified as potentially containing malware, then trigger thresholds 
associated with one or more other malware identifying processes applied to said 
computer file are adjusted to be more sensitive. 

7. (Original) A computer program product as claimed in claim 1 , wherein if said 
computer file is identified as potentially containing malware, then a trigger threshold 
associated with a heuristic malware identifying process applied to said computer file is 
set to a more sensitive level. 

8. (Original) A computer program product as claimed in claim 1 , wherein all of said 
computer file is searched for said target words. 

9. (Original) A computer program product as claimed in claim 1 , wherein only those 
portions of said computer file matching said predetermined set of contexts are searched 
for said target words. 

1 0. (Original) A computer program product as claimed in claim 1 , wherein said 
malware comprises one or more of a computer virus, a worm and a Trojan. 
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1 1 . (Currently Amended) A method of identifying a computer file as potentially 
containing malware, said method comprising the step of: 

searching within said computer file for text data containing one or more target 
words that match at least one of a word or a characteristic of a word within a 
predetermined word library; 

identifying a context within said computer file of said one or more target words; 

and 

if said context matches one or a predetermined set of contexts, then identifying 
said computer file as potentially containing malware; 

wherein said predetermined word library includes one or more of: 

words that are names associated with known malware authors; 

word format characteristics that are indicative of words being part of a 
message embedded within said computer file by a malware author: and 

word suffix characteristics that are indicative of words being part of a 
message embedded within said com puter file bv a malware author: 
wherein said predetermined set of contexts includes one or more of: 

within a script portion of a webpage: 

within a comment of a webpage; and 

within a predetermined proximity to another target word , 

12. (Cancelled) 

13. (Cancelled) 

1 4. (Original) A method as claimed in claim 1 1 , wherein, if said computer file is 
identified as potentially containing malware, then one or more malware found actions are 
triggered. 

1 5. (Original) A method as claimed in claim 14 s wherein said malware found actions 
include one or more of: 

quarantining said computer file; 
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deleting said computer file; 

issuing a warning message concerning said computer file; and 
deleting a portion of said computer file suspect of containing malware. 

16. (Original) A method as claimed in claim 1 1 , wherein, if said computer file is 
identified as potentially containing malwaie, then trigger thresholds associated with one 
or more other malware identifying processes applied to said computer file are adjusted to 
be more sensitive. 

17. (Original) A method as claimed in claim 1 1 , wherein if said computer file is 
identified as potentially containing malware, then a trigger threshold associated with a 
heuristic malware identifying process applied to said computer file is set to a more 
sensitive level. 

1 8. (Original) A method as claimed in claim 1 1 , wherein all of said computer file is 
searched for said target words. 

19. (Original) A method as claimed in claim 1 1 , wherein only those portions of said 
computer file matching said predetermined set of contexts are searched for said target 
words, 

20. (Original) A method as claimed in claim 1 1 , wherein said malware comprises one 
or more of a computer virus, a worm and a Trojan. 

21 . (Currently Amended) Apparatus including a program embodied on a computer 
readable medium for identifying a computer file as potentially containing malware, said 
apparatus comprising: 

searching logic operable to search within said computer file for text data 
containing one or more target words that match at least one of a word or a characteristic 
of a word within a predetermined word library; 
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context identifying logic operable to identify a context within said computer file 
of said one or more target words; and 

file identifying logic operable if said context matches one or a predetermined set 
of contexts to identify said computer file as potentially containing malware; 
wherein said predetermined word library includes one or more of: 

words that are names associated with known malwaie authors; 

word format cha racteristics that are indicative of words being part of a 
message embe dded within said computer file bv a malware author: and 

word suffix characteristics that are indicative of words being part of a 
message embedded within sai d computer file bv a malware author: 
wherein said pr edetermined set of contexts includes one or more of: 

within a script portion of a webpage; 

within a comment of a webpage: and 

within a predetermined proximity to another target word . 

22. (Cancelled) 

23. (Cancelled) 

24. (Original) Apparatus as claimed in claim 2 1 , wherein, if said computer file is 
identified as potentially containing malware, then malware found logic triggers one or 
more malware found actions. 

25. (Original) Apparatus as claimed in claim 24, wherein said malware found actions 
include one or more of: 

quarantining said computer file; 
deleting said computer file; 

issuing a warning message concerning said computer file; and 
deleting a portion of said computer file suspect of containing malware. 
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26. (Original) Apparatus as claimed in claim 2 1 , wherein, if said computer file is 
identified as potentially containing malware, then trigger thresholds associated with one 
or more other malware identifying processes applied to said computer file are adjusted to 
be more sensitive. 

27. (Original) Apparatus as claimed in claim 2 1 , wherein if said computer file is 
identified as potentially containing malware, then a trigger threshold associated with a 
heuristic malware identifying process applied to said computer file is set to a more 
sensitive level. 

28. (Original) Apparatus as claimed in claim 21, wherein all of said computer file is 
searched for said target words. 

29. (Original) Apparatus as claimed in claim 2 1 , wherein only those portions of said 
computer file matching said predetermined set of contexts are searched for said target 
words. 

30. (Original) Apparatus as claimed in claim 2 1 , wherein said malware comprises one 
or more of a computer virus, a worm and a Trojan. 

3 1 . (New) A computer program product as claimed in claim 1 , wherein said 
predetermined word library includes: words that are names associated with known 
malware authors; words that are indicative of being part of a message embedded within 
said computer file by a malware author; word format characteristics that are indicative of 
words being part of a message embedded within said computer file by a malware author, 
and word suffix characteristics that are indicative of words being part of a message 
embedded within said computer file by a malware author, 

32. (New) A computer program product as claimed in claim 1 , wherein said 
predetermined set of contexts includes: within a script portion of a webpage; within a 
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comment of a webpage; within executable code; and within a predetermined proximity to 
another target word 

33. (New) A computer program product as claimed in claim 1, wherein said words 
include a phonetic equivalent thereof. 

34. (New) A computer program product as claimed in claim 1, wherein said computer 
file identified as potentially containing malware is prevented from being transmitted 
outward from a mail server and is further analyzed when being transmitted inward to said 
mail server. 

35. (New) A computer program product as claimed in claim 7, wherein said heuristic 
malware identifying process is set to a more sensitive level by reducing a suspicious 
activities score required to trigger identification of said computer file as containing 
malware. 
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